#

image
image
All News

August 26, 2026

Cosmos Labs Urges Immediate Blockchain Update to Quell Exploits: Impact and Analysis

"Blockchain upgrade warning featuring Cosmos Labs logo and affected chains including MANTRA, TAC, and KiiChain, depicted with their respective icons against a dark blue background with orange accents. Cryptocurrency value crash represented by plummeting line graphs for heightened alert."

Cosmos Labs Issues Urgent Upgrade Call to Protect Blockchains from Glitches

In a recent development, Cosmos Labs issued an urgent advisory asking for chains running old versions of its Ethereum Virtual Machine (EVM) module- specifically, those below v0.6.2 and v0.7.2 – to immediately halt and upgrade their blockchain operations. This step was recommended to incorporate essential security amendments shipped with these versions.

The call for an upgrade was not targeted towards a specific network but a myriad of systems sharing an identical open-source codebase. The scale of these operations is unknown at the moment. The three chains known to implement this common codebase – MANTRA, TCA and KiiChain –are reportedly under attack, with incidents dated between August 20 and 22, leading to two of these chains clamping down operations in light of the threat. Surprisingly, no official security advisories were launched by Cosmos Labs so far to mitigate the issue.

KiiChain Bear’s $9.7 Million Brunt

KiiChain is the only network that provided a measure of the extent of the damage. Their report claims that an adversary siphoned off 148 million KII from the wallets spread across their network on August 22. The malefactor exploited identical techniques with various targets to conduct these illicit transactions. This attack drained funds amounting to nearly $9.7 million, considering an exchange rate of $0.0653/KII.

KiiChain was prompt to react to the situation by halting it at the block 9,355,723 stage, as per the incident report. Following a waiting period of 66 hours, a majority of the stolen tokens (around 80.7 million KII, or 54.4%) were frozen within attacker addresses thanks to the network suspension. These will be moved to recovery wallets once the network restarts.

The rest of the pilfered funds, approximately 67.6 million KII, have been traced to the BNB Smart Chain through an entity named Hyperlane. Of this amount, around 64.6 million KII was traded on decentralized exchanges for nearly 1.61 million BUSD, with the rest 3 million KII ending up in a KuCoin deposit address.

Underlining the Source of Vulnerability

KiiChain clarified that the underlying security vulnerability was sourced from Cosmos Code and not from KiiChain. The report suggested that three upstream weaknesses needed to align to unravel the current disruption. An anomaly in staking precompile as it rewrites a post-delegation balance back to the EVM, in addition to two undisclosed bugs in KiiChain, were highlighted as the main causes. The unaffected chains with enabling vesting accounts still face the same exploitable hazard, explaining why MANTRA and TAC were compromised in the current wave of attacks.

#

image
image

Cosmos Labs’ Disclosure Handling Under Scanner

KiiChain levelled serious accusations against Cosmos Labs regarding their policies in handling the prevailing exploit. It was claimed that Cosmos Labs published a fix for one of the three defects on August 19 in an open public repository, thereby potentially exposing the vulnerability to any malicious entities patrolling that commit. This act of publishing security fixes in the open – before the chains implementing this code could be privately intimated and given time to patch the flaw – was heavily criticized. Interestingly, chains running on the vulnerable code were only alerted of the security update two days later, leaving a precarious window for attackers to exploit the vulnerability.

Smoothening the Aftermath

In an effort to ease the strain caused by these events, KiiChain has blocked new vesting account creation temporarily and implemented two of the three fixes on an isolated system. A relaunch date for KiiChain and TAC has yet to be announced.

Cosmos Labs Under Spotlight

Cosmos Labs, yet to respond to KiiChain’s accusations, has only publicly addressed the incident twice. They asserted that a security incident is currently affecting users of the Cosmos EVM and chains in contact have been requested to halt operations.

Final words to the wise from this array of events: software solutions including blockchains are not immune from the adverse impact of defects. Proactive vigilance in identifying and patching security loopholes goes a long way in maintaining the integrity of these systems. The onus is increasingly falling on developers to exercise responsible disclosure and ensure downstream chains are kept in the loop during crucial updates and fixes.

James Carter

Financial Analyst & Content Creator | Expert in Cryptocurrency & Forex Education

James Carter is an experienced financial analyst, crypto educator, and content creator with expertise in crypto, forex, and financial literacy. Over the past decade, he has built a multifaceted career in market analysis, community education, and content strategy. At AltSignals.io, James leads content creation for English-speaking audiences, developing articles, webinars, and guides that simplify complex market trends and trading strategies. Known for his ability to make technical finance topics accessible, he empowers both new and seasoned investors to make informed decisions in the ever-evolving world of digital finance.

Latest posts by James Carter

Latest posts from the category All News

Responsive Image